webbycoin.

Unbiased intelligence for the Web3 era.

AI-Driven Crypto Crime Surges 40% as Automated Scams Reach Maturity

AI adoption across crypto crime surged 40% year-over-year, according to blockchain intelligence firm TRM Labs. The firm's 2026 AI-in-Crime Adoption Index now reads 54 out of 100 — up from roughly 28 in 2024. Scams sit at a "mature" adoption level.

AI-Driven Crypto Crime Surges 40% as Automated Scams Reach Maturity

AI-Powered Crypto Crime Hits 40% Growth — And Scams Lead the Charge

The attack surface is expanding faster than most security budgets can absorb.

The Numbers Behind the Index

TRM's data paints a clear escalation curve:

  • AI-related scam reports have risen up to 13x since 2022.
  • Deepfake-driven losses in 2026 have already surpassed full-year 2025 totals by 263%.
  • Digital-asset hacks hit a record 201 incidents in H1 2026 — more than double the prior-year pace.
  • North Korea-linked activity accounted for roughly $600 million, or 61% of H1 losses.

The skill floor collapsed. No-code ransomware kits now sell for $400–$1,200. One person with a subscription replaces what used to require a full operator team.

Attack Vectors Worth Watching

Two developments stand out for their systemic implications.

JadePuffer — disclosed last month — is the first fully agentic ransomware. An AI agent handled reconnaissance, credential theft, lateral movement, and encryption end-to-end. No human in the loop. TRM's global head of policy described it as the shape of attacks at scale against critical infrastructure.

AI-assisted vulnerability discovery is the second vector. In June, a security engineer used AI to surface a critical flaw in Zcash's Orchard transaction pool — one that could have enabled unlimited counterfeit token creation. The implication: AI doesn't just scale social engineering. It compresses the exploit discovery cycle for protocol-level bugs.

What This Means for On-Chain Risk

Much of the measured criminal activity ultimately moves value on public blockchains. That makes on-chain flow data a reasonable proxy for broader threat patterns — and a monitoring priority for any protocol, exchange, or DeFi operator managing meaningful TVL.

The threat model is shifting. AI hasn't invented new crimes. It removed constraints on old ones — scaling deepfake impersonation, automating exploit chains, and industrializing fake identity at a cost point accessible to low-skill actors. Exchanges, DEXs, and token launch platforms sit squarely in the blast radius.

Sustainability verdict: the cost of attack is falling; the cost of defense is not. Budget accordingly.